Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- curl -XPUT localhost:9200/_template/fixstrings_bro -d '{
- "template": "bro-*",
- "mappings": {
- "http": {
- "properties": {
- "host": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_p": {
- "type": "long"
- },
- "id.resp_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.resp_p": {
- "type": "long"
- },
- "method": {
- "type": "string",
- "index": "not_analyzed"
- },
- "orig_fuids": {
- "type": "string",
- "index": "not_analyzed"
- },
- "orig_mime_types": {
- "type": "string",
- "index": "not_analyzed"
- },
- "referrer": {
- "type": "string",
- "index": "not_analyzed"
- },
- "request_body_len": {
- "type": "long"
- },
- "resp_fuids": {
- "type": "string",
- "index": "not_analyzed"
- },
- "resp_mime_types": {
- "type": "string",
- "index": "not_analyzed"
- },
- "response_body_len": {
- "type": "long"
- },
- "status_code": {
- "type": "long"
- },
- "status_msg": {
- "type": "string",
- "index": "not_analyzed"
- },
- "tags": {
- "type": "string",
- "index": "not_analyzed"
- },
- "trans_depth": {
- "type": "long"
- },
- "ts": {
- "type": "long"
- },
- "uid": {
- "type": "string",
- "index": "not_analyzed"
- },
- "uri": {
- "type": "string",
- "index": "not_analyzed"
- },
- "user_agent": {
- "type": "string",
- "index": "not_analyzed"
- }
- }
- },
- "known_hosts": {
- "properties": {
- "host": {
- "type": "string",
- "index": "not_analyzed"
- },
- "ts": {
- "type": "long"
- }
- }
- },
- "known_services": {
- "properties": {
- "host": {
- "type": "string",
- "index": "not_analyzed"
- },
- "port_num": {
- "type": "long"
- },
- "port_proto": {
- "type": "string",
- "index": "not_analyzed"
- },
- "service": {
- "type": "string",
- "index": "not_analyzed"
- },
- "ts": {
- "type": "long"
- }
- }
- },
- "dpd": {
- "properties": {
- "analyzer": {
- "type": "string",
- "index": "not_analyzed"
- },
- "failure_reason": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_p": {
- "type": "long"
- },
- "id.resp_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.resp_p": {
- "type": "long"
- },
- "proto": {
- "type": "string",
- "index": "not_analyzed"
- },
- "ts": {
- "type": "long"
- },
- "uid": {
- "type": "string",
- "index": "not_analyzed"
- }
- }
- },
- "weird": {
- "properties": {
- "id.orig_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_p": {
- "type": "long"
- },
- "id.resp_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.resp_p": {
- "type": "long"
- },
- "name": {
- "type": "string",
- "index": "not_analyzed"
- },
- "notice": {
- "type": "boolean"
- },
- "peer": {
- "type": "string",
- "index": "not_analyzed"
- },
- "ts": {
- "type": "long"
- },
- "uid": {
- "type": "string",
- "index": "not_analyzed"
- }
- }
- },
- "smtp": {
- "properties": {
- "helo": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_p": {
- "type": "long"
- },
- "id.resp_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.resp_p": {
- "type": "long"
- },
- "is_webmail": {
- "type": "boolean"
- },
- "last_reply": {
- "type": "string",
- "index": "not_analyzed"
- },
- "path": {
- "type": "string",
- "index": "not_analyzed"
- },
- "tls": {
- "type": "boolean"
- },
- "trans_depth": {
- "type": "long"
- },
- "ts": {
- "type": "long"
- },
- "uid": {
- "type": "string",
- "index": "not_analyzed"
- }
- }
- },
- "ssl": {
- "properties": {
- "cert_chain_fuids": {
- "type": "string",
- "index": "not_analyzed"
- },
- "cipher": {
- "type": "string",
- "index": "not_analyzed"
- },
- "curve": {
- "type": "string",
- "index": "not_analyzed"
- },
- "established": {
- "type": "boolean"
- },
- "id.orig_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_p": {
- "type": "long"
- },
- "id.resp_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.resp_p": {
- "type": "long"
- },
- "issuer": {
- "type": "string",
- "index": "not_analyzed"
- },
- "next_protocol": {
- "type": "string",
- "index": "not_analyzed"
- },
- "resumed": {
- "type": "boolean"
- },
- "server_name": {
- "type": "string",
- "index": "not_analyzed"
- },
- "subject": {
- "type": "string",
- "index": "not_analyzed"
- },
- "ts": {
- "type": "long"
- },
- "uid": {
- "type": "string",
- "index": "not_analyzed"
- },
- "validation_status": {
- "type": "string",
- "index": "not_analyzed"
- },
- "version": {
- "type": "string",
- "index": "not_analyzed"
- }
- }
- },
- "dns": {
- "properties": {
- "AA": {
- "type": "boolean"
- },
- "RA": {
- "type": "boolean"
- },
- "RD": {
- "type": "boolean"
- },
- "TC": {
- "type": "boolean"
- },
- "Z": {
- "type": "long"
- },
- "id.orig_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_p": {
- "type": "long"
- },
- "id.resp_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.resp_p": {
- "type": "long"
- },
- "proto": {
- "type": "string",
- "index": "not_analyzed"
- },
- "qclass": {
- "type": "long"
- },
- "qclass_name": {
- "type": "string",
- "index": "not_analyzed"
- },
- "qtype": {
- "type": "long"
- },
- "qtype_name": {
- "type": "string",
- "index": "not_analyzed"
- },
- "query": {
- "type": "string",
- "index": "not_analyzed"
- },
- "rcode": {
- "type": "long"
- },
- "rcode_name": {
- "type": "string",
- "index": "not_analyzed"
- },
- "rejected": {
- "type": "boolean"
- },
- "trans_id": {
- "type": "long"
- },
- "ts": {
- "type": "long"
- },
- "uid": {
- "type": "string",
- "index": "not_analyzed"
- }
- }
- },
- "snmp": {
- "properties": {
- "community": {
- "type": "string",
- "index": "not_analyzed"
- },
- "duration": {
- "type": "double"
- },
- "get_bulk_requests": {
- "type": "long"
- },
- "get_requests": {
- "type": "long"
- },
- "get_responses": {
- "type": "long"
- },
- "id.orig_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_p": {
- "type": "long"
- },
- "id.resp_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.resp_p": {
- "type": "long"
- },
- "set_requests": {
- "type": "long"
- },
- "ts": {
- "type": "long"
- },
- "uid": {
- "type": "string",
- "index": "not_analyzed"
- },
- "version": {
- "type": "string",
- "index": "not_analyzed"
- }
- }
- },
- "x509": {
- "properties": {
- "basic_constraints.ca": {
- "type": "boolean"
- },
- "basic_constraints.path_len": {
- "type": "long"
- },
- "certificate.exponent": {
- "type": "string",
- "index": "not_analyzed"
- },
- "certificate.issuer": {
- "type": "string",
- "index": "not_analyzed"
- },
- "certificate.key_alg": {
- "type": "string",
- "index": "not_analyzed"
- },
- "certificate.key_length": {
- "type": "long"
- },
- "certificate.key_type": {
- "type": "string",
- "index": "not_analyzed"
- },
- "certificate.not_valid_after": {
- "type": "long"
- },
- "certificate.not_valid_before": {
- "type": "long"
- },
- "certificate.serial": {
- "type": "string",
- "index": "not_analyzed"
- },
- "certificate.sig_alg": {
- "type": "string",
- "index": "not_analyzed"
- },
- "certificate.subject": {
- "type": "string",
- "index": "not_analyzed"
- },
- "certificate.version": {
- "type": "long"
- },
- "id": {
- "type": "string",
- "index": "not_analyzed"
- },
- "san.dns": {
- "type": "string",
- "index": "not_analyzed"
- },
- "ts": {
- "type": "long"
- }
- }
- },
- "sip": {
- "properties": {
- "call_id": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_p": {
- "type": "long"
- },
- "id.resp_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.resp_p": {
- "type": "long"
- },
- "method": {
- "type": "string",
- "index": "not_analyzed"
- },
- "request_body_len": {
- "type": "string",
- "index": "not_analyzed"
- },
- "request_from": {
- "type": "string",
- "index": "not_analyzed"
- },
- "request_path": {
- "type": "string",
- "index": "not_analyzed"
- },
- "request_to": {
- "type": "string",
- "index": "not_analyzed"
- },
- "seq": {
- "type": "string",
- "index": "not_analyzed"
- },
- "trans_depth": {
- "type": "long"
- },
- "ts": {
- "type": "long"
- },
- "uid": {
- "type": "string",
- "index": "not_analyzed"
- },
- "uri": {
- "type": "string",
- "index": "not_analyzed"
- },
- "user_agent": {
- "type": "string",
- "index": "not_analyzed"
- }
- }
- },
- "notice": {
- "properties": {
- "actions": {
- "type": "string",
- "index": "not_analyzed"
- },
- "dropped": {
- "type": "boolean"
- },
- "dst": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_p": {
- "type": "long"
- },
- "id.resp_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.resp_p": {
- "type": "long"
- },
- "msg": {
- "type": "string",
- "index": "not_analyzed"
- },
- "note": {
- "type": "string",
- "index": "not_analyzed"
- },
- "p": {
- "type": "long"
- },
- "peer_descr": {
- "type": "string",
- "index": "not_analyzed"
- },
- "proto": {
- "type": "string",
- "index": "not_analyzed"
- },
- "src": {
- "type": "string",
- "index": "not_analyzed"
- },
- "sub": {
- "type": "string",
- "index": "not_analyzed"
- },
- "suppress_for": {
- "type": "double"
- },
- "ts": {
- "type": "long"
- },
- "uid": {
- "type": "string",
- "index": "not_analyzed"
- }
- }
- },
- "files": {
- "properties": {
- "analyzers": {
- "type": "string",
- "index": "not_analyzed"
- },
- "conn_uids": {
- "type": "string",
- "index": "not_analyzed"
- },
- "depth": {
- "type": "long"
- },
- "duration": {
- "type": "double"
- },
- "filename": {
- "type": "string",
- "index": "not_analyzed"
- },
- "fuid": {
- "type": "string",
- "index": "not_analyzed"
- },
- "is_orig": {
- "type": "boolean"
- },
- "local_orig": {
- "type": "boolean"
- },
- "md5": {
- "type": "string",
- "index": "not_analyzed"
- },
- "mime_type": {
- "type": "string",
- "index": "not_analyzed"
- },
- "missing_bytes": {
- "type": "long"
- },
- "overflow_bytes": {
- "type": "long"
- },
- "rx_hosts": {
- "type": "string",
- "index": "not_analyzed"
- },
- "seen_bytes": {
- "type": "long"
- },
- "sha1": {
- "type": "string",
- "index": "not_analyzed"
- },
- "source": {
- "type": "string",
- "index": "not_analyzed"
- },
- "timedout": {
- "type": "boolean"
- },
- "total_bytes": {
- "type": "long"
- },
- "ts": {
- "type": "long"
- },
- "tx_hosts": {
- "type": "string",
- "index": "not_analyzed"
- }
- }
- },
- "intel": {
- "properties": {
- "id.orig_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_p": {
- "type": "long"
- },
- "id.resp_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.resp_p": {
- "type": "long"
- },
- "seen.indicator": {
- "type": "string",
- "index": "not_analyzed"
- },
- "seen.indicator_type": {
- "type": "string",
- "index": "not_analyzed"
- },
- "seen.node": {
- "type": "string",
- "index": "not_analyzed"
- },
- "seen.where": {
- "type": "string",
- "index": "not_analyzed"
- },
- "sources": {
- "type": "string",
- "index": "not_analyzed"
- },
- "ts": {
- "type": "long"
- },
- "uid": {
- "type": "string",
- "index": "not_analyzed"
- }
- }
- },
- "software": {
- "properties": {
- "host": {
- "type": "string",
- "index": "not_analyzed"
- },
- "name": {
- "type": "string",
- "index": "not_analyzed"
- },
- "software_type": {
- "type": "string",
- "index": "not_analyzed"
- },
- "ts": {
- "type": "long"
- },
- "unparsed_version": {
- "type": "string",
- "index": "not_analyzed"
- },
- "version.addl": {
- "type": "string",
- "index": "not_analyzed"
- },
- "version.major": {
- "type": "long"
- },
- "version.minor": {
- "type": "long"
- },
- "version.minor2": {
- "type": "long"
- },
- "version.minor3": {
- "type": "long"
- }
- }
- },
- "conn": {
- "properties": {
- "conn_state": {
- "type": "string",
- "index": "not_analyzed"
- },
- "duration": {
- "type": "double"
- },
- "history": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.orig_p": {
- "type": "long"
- },
- "id.resp_h": {
- "type": "string",
- "index": "not_analyzed"
- },
- "id.resp_p": {
- "type": "long"
- },
- "local_orig": {
- "type": "boolean"
- },
- "local_resp": {
- "type": "boolean"
- },
- "missed_bytes": {
- "type": "long"
- },
- "orig_bytes": {
- "type": "long"
- },
- "orig_ip_bytes": {
- "type": "long"
- },
- "orig_pkts": {
- "type": "long"
- },
- "proto": {
- "type": "string",
- "index": "not_analyzed"
- },
- "resp_bytes": {
- "type": "long"
- },
- "resp_ip_bytes": {
- "type": "long"
- },
- "resp_pkts": {
- "type": "long"
- },
- "service": {
- "type": "string",
- "index": "not_analyzed"
- },
- "ts": {
- "type": "long"
- },
- "uid": {
- "type": "string",
- "index": "not_analyzed"
- }
- }
- },
- "app_stats": {
- "properties": {
- "app": {
- "type": "string",
- "index": "not_analyzed"
- },
- "bytes": {
- "type": "long"
- },
- "hits": {
- "type": "long"
- },
- "ts": {
- "type": "long"
- },
- "ts_delta": {
- "type": "double"
- },
- "uniq_hosts": {
- "type": "long"
- }
- }
- }
- }
- }'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement